Security Software Engineer, IAM

New
V
VercelIdentity and access management
Remote - United StatesFull-TimeSenior
SalaryThe San Francisco, CA base pay range for this role is $208,000 - $312,000.
Apply NowOpens the employer's application page

Job Details

Experience
7+ years of experience in identity, access management, or platform security engineering
Required Skills
PythonOAuthGoRESTful APIsTerraform

Requirements

  • Have 7+ years of experience in identity, access management, or platform security engineering.
  • Have experience building internal tools or self-service platforms, rather than only administering existing products.
  • Be proficient in a production language such as TypeScript/Node.js, Go, or Python.
  • Be comfortable designing and consuming REST APIs and shipping and operating reliable services.
  • Be proficient in Terraform and committed to managing IAM infrastructure as code; experience migrating existing systems is preferred.
  • Have implementation-level experience with OAuth2, OIDC, SAML, and SCIM, including identity-related failure modes.
  • Have experience designing IAM at scale across corporate environments, including Okta or an equivalent, and production environments using AWS or GCP IAM.
  • Understand corporate IAM areas such as SSO, MFA, lifecycle management, and API-driven automation.
  • Understand production IAM areas such as service accounts, roles, and workload identity federation.
  • Be able to collaborate across Engineering, IT, Compliance, and Security teams.
  • Be comfortable operating autonomously and owning decisions.

Responsibilities

  • Own IAM strategy across corporate, production, and product environments, including the connection between corporate IAM and product and production IAM.
  • Migrate Okta and related IAM configuration to Terraform so identity changes are reviewed, tested, and versioned.
  • Build self-service access governance tooling, including just-in-time access, so team and system owners can define, request, and time-bound access.
  • Own provisioning, deprovisioning, and access review workflows, with audit evidence generated by the system.
  • Work with the Accounts team to identify how internal IAM connects with product IAM, including team and project roles, enterprise SSO, SCIM, and API tokens.
  • Design and enforce least-privilege access controls across cloud, SaaS, and production infrastructure.
  • Partner with platform and engineering teams to incorporate IAM during system design.
  • Help define and build identity and access approaches for agents.
View Full Description & ApplyYou'll be redirected to the employer's site
The San Francisco, CA base pay range for this role is $208,000 - $312,000.
Apply Now